The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro
A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been classified as critical. This affect
A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this iss
A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by thi
A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 2.0. Affected is
A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affec
When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects
A vulnerability has been found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this vulner
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declar
aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the n
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response log
A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. Affected by this
A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. This vulnerability affe
A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System 1.2. This affects an un
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been rated as critical. Affected by thi
Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules define
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as critical. Affected by
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. Affected i
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This issue affects
A vulnerability has been found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This vulnerabi
A vulnerability, which was classified as critical, was found in CodeAstro Real Estate Management System 1.0. This affect
A vulnerability, which was classified as critical, has been found in CodeAstro Real Estate Management System 1.0. Affect
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject`
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `<iframe
FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedl
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validatio
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input vali
A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the fu
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'n
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacke
A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an
A vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise could a
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authentic
A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) co
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMin
Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbi
An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo
An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privi
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile pro
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile pro
Sensitive information disclosure due to SSRF. The following products are affected: Acronis Cyber Protect 16 (Windows, Li
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started